Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 20.04 AccountsService Critical Exec Command Threat USN-8580-2

ubuntu
Calendar Grey July 21, 2026
Scroller Ubuntu
AccountsService update for Ubuntu addresses critical security flaws that allow local attackers to execute commands as admins.
AccountsService could be made to run programs as an administrator if it opened a specially crafted file.

Summary

AccountsService could be made to run programs as an administrator if it

opened a specially crafted file.

Software Description:

- accountsservice: query and manipulate user account information

Details:

USN-8580-1 fixed vulnerabilities in AccountsService. This update provides

the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,

Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that the Ubuntu-specific SetLanguage patch to

AccountsService incorrectly handled dropping privileges. A local attacker

could use this issue to execute arbitrary commands as an administrator.

(CVE-2026-61897)

It was discovered that the Ubuntu-specific SetLanguage helpers for

AccountsService incorrectly handled parsing configuration files. A local

attacker could use this issue to execute arbitrary commands.

(CVE-2026-61898)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  accountsservice                 0.6.55-0ubuntu12~20.04.7+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  accountsservice                 0.6.45-1ubuntu1.3+esm2
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  accountsservice                 0.6.40-2ubuntu11.6+esm2
                                  Available with Ubuntu Pro

Ubuntu 14.04 LTS
  accountsservice                 0.6.35-0ubuntu7.3+esm4
                                  Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8580-2

https://ubuntu.com/security/notices/USN-8580-1

CVE-2026-61897, CVE-2026-61898

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8580-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.